PT-2006-5281 · Php · Php

Published

2006-08-31

·

Updated

2018-10-30

·

CVE-2006-4481

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
The (1) file exists and (2) imap reopen functions in PHP before 5.1.5 do not check for the safe mode and open basedir settings, which allows local users to bypass the settings. NOTE: the error log function is covered by CVE-2006-3011, and the imap open function is covered by CVE-2006-1017.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4481

Affected Products

Php